AURAIUM
Detection Study · NFRA Order 28/2023

We rebuilt the Coffee Day fraud as a ledger. Our AI flagged every entry.

A reconstruction of the fraud patterns NFRA found in the Coffee Day group — and a test of whether full-population AI testing surfaces what sampling did not.

What this is: a reconstruction, not real data. No company's general ledger is public — not Coffee Day's, not anyone's. What is public is NFRA's order against the auditors, which describes the fraudulent entries in detail. We rebuilt a ledger from that description and ran Auraium over it.

The question we wanted answered: would an AI running across 100% of the transactions have surfaced what a real audit team, working from samples, did not?

What NFRA found

In August 2023, NFRA issued orders against the auditors of the Coffee Day group. The findings, in the regulator's own words:

  • ₹3,535 crore was diverted from seven CDEL subsidiaries to MACEL, a promoter-owned entity
  • The diversion was routed through complex intra-group circular transfers
  • Outstanding receivables from MACEL were understated using uncashed cheque entries booked as loan repayments
  • The auditors were charged with failing to detect evergreening of loans through structured circular transactions

The auditors did not miss this because they were negligent in some obvious way. They missed it because each individual entry, viewed alone, looked like ordinary inter-company activity. That is exactly what sampling is bad at.

How we rebuilt it

We generated a synthetic general journal for a fictional beverage group — 2,659 rows covering FY 2019-20. Ordinary operating activity makes up the bulk of it: sales, purchases, payroll, rent, vendor payments, with realistic log-normal amounts and weekday-skewed dates.

Into that we seeded 59 entries reproducing the four patterns NFRA described:

Pattern Entries What it looks like in the ledger
Circular intra-group transfers 32 Round-sum advances moving through two or three subsidiaries over a few days, ending at the promoter-owned entity
Uncashed cheque "repayments" 7 Credits to the related-party loan account referencing a cheque number, clustered in Q4
Evergreening 12 A repayment received, then a near-identical fresh disbursal to the same entity days later
Period-end manual journals 8 Large adjustment entries posted on quarter-end and year-end dates
Total seeded 59 2.22% of the file

The seeded proportion was deliberately in the range a real ledger would produce, so the test wasn't trivial. We then uploaded it to Auraium as a General Journal and ran a standard audit — no special configuration, no tuning for this file.

The result

59 of 59
Seeded entries flagged · zero missed
Pattern Seeded Caught
Circular intra-group transfers 32 32
Uncashed cheque repayments 7 7
Evergreening 12 12
Period-end manual journals 8 8
Total 59 59
2,659
Rows analysed
68
Rows flagged
0.35%
False positive rate
48
At highest risk tier

Every flagged entry came with a written explanation: what the entry was, why it was unusual, which red flags applied, what could not be determined from the data, and three specific next steps for the auditor.

What this does not prove

We would rather say this ourselves than have you find it

Auraium caught these primarily on magnitude and timing, not on structure. The seeded transfers were ₹2.5–15 crore in a ledger where the median entry was ₹85,000. The system flagged them as extreme outliers against the account baseline and as period-end postings. It did not announce "this is a circular transfer" or "this is evergreening" — it announced "this entry is deeply abnormal for this account, here is why, go look at it."

For an auditor, that distinction matters less than it sounds. The output is a shortlist of entries warranting documentation and follow-up, which is precisely what the audit standards require and precisely what was absent in the NFRA orders. But we are not claiming pattern recognition we have not demonstrated.

This is synthetic data. We built the ledger, which means we knew what was in it. It is a controlled test of detection, not evidence of performance on any real client file.

Why this matters for your firm

Read the NFRA orders closely and notice what they actually punish. Not "you failed to catch a fraud." They punish insufficient audit evidence, inadequate documentation, and failure to apply professional skepticism.

Under Section 132(4) of the Companies Act, proven professional misconduct carries a penalty of not less than ₹1 lakh — extending to five times fees received for an individual, ten times for a firm — plus debarment from audit work for six months to ten years. Real orders have landed at ₹5 lakh with a five-year ban, and ₹50 lakh on a firm with ₹10 lakh on the engagement partner personally.

NFRA's jurisdiction covers Public Interest Entities, so most SME audit work sits outside it. But Section 143(12) — the obligation to report fraud of ₹1 crore or more — applies to every statutory auditor of every company, and NFRA has stated publicly that auditors are not meeting it.

Sampling gives you a defensible answer to "did you look?" only for the 5–20% you sampled. Full-population testing gives you a timestamped record that you examined every entry, flagged the ones that mattered, and documented why.

That is the actual product. Not catching more fraud — being able to show what you looked at.

Try it on your own data

We will run one of your client ledgers free. Export it as CSV or Excel, anonymise it if you prefer — the counterparty names don't matter to the detection. We return the full report within 24 hours.

Your data is deleted after the run, never used for training, and we'll sign an NDA before you send anything.

Reconstruction based on NFRA Order 28/2023 dated 18.08.2023 and related orders in the matter of the Coffee Day group. Entity names in the synthetic ledger are fictional. The underlying generator script is available on request.